Skip to main content

Settings

Configure your organization's team members, API keys, branding, and vendor-review policy.

Overview

The Settings section allows administrators to:

  • Manage team members and invite users
  • Configure your Anthropic API key for Bring-Your-Own-Key (BYOK) usage
  • Upload a custom organization logo (plan-dependent)
  • Govern vendor security requirements, AI instructions, review mode, and document retention across parent and child organizations
  • Choose whether vendor-review source documents are deleted after initial analysis
warning

Write access depends on both your role and the selected organization's governance mode. Read-only administrators can view settings but cannot change them. A child administrator can change vendor settings only when the parent organization has selected Child organization manages its settings for that child.


Accessing Settings

  1. Log in at https://app.canirunthat.com
  2. Click Settings in the main navigation menu
  3. Use the available settings cards for your role and organization

Logo Branding

Custom Logo Upload

The Branding card allows you to upload a custom logo for your organization:

  1. Logo Upload — Upload your company logo (PNG, JPG, or GIF format)
    • Maximum file size: 5 MB
    • Recommended: Square format for best appearance
  2. Logo Display — How your logo appears in the platform depends on your plan:
    • Tier 2 Plan: Logo displays alongside the application name
    • Tier 3+ Plan: Logo fully replaces the application branding
  1. Go to Settings > Branding card
  2. Click Upload Logo and select a PNG, JPG, or GIF file from your computer (max 5 MB)
  3. Click Upload Logo to confirm the upload
  4. Once uploaded, a preview of your logo will display in the card

To remove your custom logo:

  1. Go to Settings > Branding card
  2. If a logo is already uploaded, a Delete Logo button will appear
  3. Click Delete Logo to remove the custom branding
  4. Confirm the deletion when prompted

Plan Availability

Logo branding requires Tier 2 or higher plan tier. If branding is unavailable, you'll see a message like:

Logo branding is not available on your current plan.
Upgrade to Tier 2 or higher to customize your organization's logo.

Contact your administrator to upgrade your plan.


Anthropic API Key (BYOK)

Overview

The Anthropic API Key card allows you to configure your own Anthropic API key for Bring-Your-Own-Key (BYOK) usage. When configured, your key is used for all security analysis in your organization.

Saving Your API Key

  1. Go to Settings > Anthropic API Key card
  2. In the Anthropic API Key password input field, enter your API key
    • Key format must start with sk-ant-
  3. Click Save Key
  4. A success message shows "API key saved successfully"
  5. Your key status updates to show "Configured — sk-ant-***xxxx" (masked)

Key Management

The Current Status field shows:

  • Configured — Your key is saved and active. A masked preview is displayed (e.g., sk-ant-***xxxx)
  • Not configured — No key is currently set. Configure one to enable BYOK usage

Plan and Source Restrictions

  • BYOK not available: If you see "API key management is not available on your current plan," your organization doesn't support BYOK yet

For complete BYOK setup instructions and troubleshooting, see the BYOK Guide.


Vendor Settings Across Parent and Child Organizations

Vendor settings are one governed bundle containing:

  • Vendor security requirements
  • Vendor AI instructions
  • Vendor review mode
  • Vendor review document retention

Parent organization settings are the default for every child organization. Parent administrators use the Organization dropdown in the Vendor Settings Scope card to select the parent or an active child. The four vendor settings cards below the selector always show the effective bundle for that selection.

Child Governance Modes

For each child, a parent administrator can select one of three modes:

ModeEffective settingsWho can change them
Follow parent organizationThe parent's current bundle, updated dynamically whenever the parent changes itParent administrators edit the parent bundle; the child view is read-only
Child organization manages its settingsA separate child-specific bundleChild administrators and parent administrators
Parent manages child-specific settingsA separate child-specific bundleParent administrators only; child users can view it

Changing between the two custom modes preserves the child's existing bundle. Returning to Follow parent organization makes the custom bundle dormant rather than deleting it, so it is available if custom control is enabled again later.

Initial Settings for a Custom Child Bundle

The first time a child moves from Follow parent organization to either custom mode, the parent administrator chooses one initialization source:

  • Copy the parent organization's current settings — Copies the parent's current AI instructions, review mode, retention setting, and active security requirements.
  • Start from RepoRisk platform defaults — Starts with no custom AI instructions, Chill Mode, source-document retention enabled, and a point-in-time copy of the active platform security requirement library.

This is a one-time initialization choice. Later governance changes preserve the initialized bundle and its original source. If no active platform requirements are available, RepoRisk does not create a partial child bundle; the administrator can retry after the platform library is available.

note

Vendor reviews resolve settings from the vendor's persisted parent and child ownership when analysis starts. Changing a browser dropdown cannot redirect an existing vendor review to another organization's policy.


Vendor Security Requirements

The Vendor Security Requirements card defines the controls used to evaluate vendor documentation. Administrators with write access to the selected scope can:

  • Add, edit, and deactivate requirements
  • Assign Deal Breaker, Highly Desired, Preferred, or Optional severity
  • Import selected controls from the recommended platform library
  • Extract proposed requirements from policy text, PDF, DOCX, or TXT files and review them before import

When a child follows the parent, it always uses the parent's current active requirements. A custom child bundle receives its own materialized requirement set and no longer combines parent and child rows at runtime.


Vendor AI Instructions

The Vendor AI Instructions card lets an administrator with write access provide organization-specific context that is included during vendor security analysis.

When to Use

Use this field to tailor vendor evaluations to your organization's policies and risk appetite:

  • State your compliance framework (e.g., "We follow SOC 2 Type II and HIPAA")
  • Call out vendor categories requiring stricter review
  • Specify certifications or contractual clauses your procurement policy mandates
  • Provide industry-specific context the AI should consider

Configuring Vendor AI Instructions

  1. Go to Settings > Vendor AI Instructions card
  2. Enter your context text in the textarea (up to 4,000 characters)
  3. Click Save Instructions
  4. A success message confirms the instructions are saved

All future vendor analysis runs will include this context in the AI evaluation prompt.

Clearing Instructions

To remove the instructions, clear the textarea and click Save Instructions.


Vendor Review Mode

The Vendor Review Mode card controls how the AI evaluates vendor evidence:

  • Chill Mode — The platform default. Evaluates whether the evidence meets the intent of each requirement and focuses follow-up questions on material gaps or warning signs.
  • Strict Mode — Applies more rigorous scrutiny to qualifiers, scope limitations, and alternative controls.

The effective mode is resolved when each analysis task starts. A custom child bundle can therefore use a different review mode from its parent without changing the parent's reviews.


Vendor Review Document Retention

Administrators with write access to the selected scope can use the Vendor Review Document Retention card to reduce retained source data:

  1. Go to Settings > Vendor Review Document Retention.
  2. Enable Delete source documents after initial analysis.
  3. Review the permanent-deletion warning and click Save.

Delete source documents after initial analysis is off in the platform defaults, so vendor review documents are retained by default. The setting applies only to vendor reviews created after the change is saved. Each review keeps the effective setting that was active when that review was created. Enabling or disabling it later does not change existing reviews and does not delete historical documents.

When enabled, documents remain available throughout upload, text extraction, and initial AI analysis. RepoRisk first saves the initial findings, summary, recommendation, and generated questions. It then permanently deletes the source objects from document storage. Metadata, citations, findings, questions, responses, and audit history remain available.

warning

Deleted source files cannot be viewed, downloaded, or restored. Follow-up questions and response analysis use the saved questions, findings, responses, organization context, and summary instead of revisiting the original documents. Follow-up quality may therefore be degraded.

Read-only administrators can view this setting but cannot change it. A child administrator can change it only in Child organization manages its settings mode.


Best Practices

Security Best Practices

  1. Upload Organization Logo — Add your company logo to personalize the platform (if your plan supports it)
  2. Manage Team Access Carefully — Grant admin role only to trusted team members who need Settings access
  3. Rotate API Keys — Regularly update your Anthropic API key for security
  4. Audit Team Membership — Periodically review team members and remove inactive or departed accounts

Operational Best Practices

  1. Keep Logo Current — Update your organization logo if you rebrand
  2. Review Team Members Regularly — Ensure team member roles still match their current responsibilities

Troubleshooting

Settings Changes Not Saved

If your changes don't save:

  1. Ensure all required fields are filled
  2. Click Save and wait for a confirmation message
  3. Refresh the page and verify the changes took effect
  4. Contact Support if the issue persists

Child Vendor Settings Are Read-Only

Check the governance explanation in Vendor Settings Scope:

  • Follow parent organization means the child is dynamically using the parent bundle.
  • Parent manages child-specific settings means only a parent administrator can modify the child bundle.
  • A read-only administrator cannot make changes in any mode.

Only a parent administrator can change a child's governance mode.

API Key Validation Failed

See the BYOK Troubleshooting guide for help with API key issues.

Cannot Access Settings

If you see "You do not have permission to access Settings":

  1. You must be an admin user to access Settings
  2. Contact your organization administrator to request admin access
  3. Ask your administrator to upgrade your role from Member to Admin

Next Steps

  • Manage Team Members — Invite team members and configure roles in Team Management
  • Configure BYOK — Set up your own Anthropic API key in BYOK Configuration
  • Run Vendor Reviews — Use vendor AI instructions and security requirements in Vendor Security Review
  • Manage Child Organizations — Review membership, BYOK, branding, and isolation behavior in Sub-Organizations